Impact
Concurrent execution using a shared resource with improper synchronization ("race condition") in the Remote Desktop Client allows an unauthorized attacker to execute code over a network. The vulnerability permits code execution with the privileges of the client process, which could potentially allow full system compromise without user interaction. This flaw falls under the listed CWEs involving improper synchronization, use-after-free, and buffer overflow.
Affected Systems
Affected are the Remote Desktop client for Windows Desktop and its Windows App Client, as well as all listed Windows 10 and Windows 11 releases from version 1607 to and the corresponding Windows Server versions from 2012 to 2025. The vulnerability spans both x86 and x64 architectures, including ARM64 for newer Windows 11 builds.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the EPSS score of < 1% indicates a very low but nonzero exploitation probability. The lack of a KEV listing does not diminish the risk: the vulnerability can be exploited remotely over the network by an unauthorized actor. Based on the description, it is inferred that the likely attack vector is a network‑based Remote Desktop session, where an attacker sends malicious packets to trigger the race condition and achieve remote code execution. The impact on confidentiality, integrity, and availability is significant, as full system control can be obtained without user interaction, though this is also an inferred consequence.
OpenCVE Enrichment